CSIDB logo
Incident

Free SAS

Incident posture

Attack window
Jan 2024
Location
France
Status
Historical
CIA posture
Available to members
Updated
2026-01-04 21:58

Linked entities

Victim
Free SAS
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Free Mobile experienced a cyberattack compromising personal data of some subscribers via unauthorized access to a management tool. The breach did not affect passwords, payment information, or communication contents, and caused no operational disruptions. The company filed a legal complaint, notified regulatory authorities, and began informing impacted customers via email while implementing security enhancements to terminate the incident and prevent future breaches.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Free, France's second-largest telecommunications operator, confirmed on October 26, 2024, that it had suffered a cyberattack targeting a management tool within its systems. This breach resulted in unauthorized access to a subset of personal data associated with certain subscriber accounts. The company issued a public statement via Agence France-Presse clarifying the scope of compromised information, explicitly stating that no passwords, banking card details, or communication contents—including emails, SMS messages, or voicemails—were exposed during the incident. Neither the precise date of the attack nor the full extent of impacted accounts was disclosed publicly. Free emphasized that its operational services remained unaffected throughout the event, with no disruption to customer-facing activities detected.

The operator initiated multiple response protocols following the breach discovery. Free filed a formal criminal complaint with the Paris prosecutor's office and notified France's National Commission on Informatics and Liberty (CNIL) and National Agency for the Security of Information Systems (ANSSI) in compliance with national data protection regulations. Affected subscribers received or were scheduled to receive individual email notifications detailing the incident. Company representatives asserted all necessary measures had been implemented immediately to terminate the attack's progression and enhance the security posture of their information systems. This incident occurred approximately five weeks after competitor SFR disclosed a separate data leak involving customer banking information, though no operational or tactical connections between the two events were established in available reporting.

Sources

Sources available to members: 1 source.

CSIDB